// For flags

CVE-2005-3532

 

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2005-11-16 CVE Reserved
  • 2005-12-11 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Double Precision Incorporated
Search vendor "Double Precision Incorporated"
Courier Mail Server
Search vendor "Double Precision Incorporated" for product "Courier Mail Server"
0.37.3
Search vendor "Double Precision Incorporated" for product "Courier Mail Server" and version "0.37.3"
-
Affected
Double Precision Incorporated
Search vendor "Double Precision Incorporated"
Courier Mail Server
Search vendor "Double Precision Incorporated" for product "Courier Mail Server"
0.46
Search vendor "Double Precision Incorporated" for product "Courier Mail Server" and version "0.46"
-
Affected
Double Precision Incorporated
Search vendor "Double Precision Incorporated"
Courier Mail Server
Search vendor "Double Precision Incorporated" for product "Courier Mail Server"
0.47
Search vendor "Double Precision Incorporated" for product "Courier Mail Server" and version "0.47"
-
Affected
Double Precision Incorporated
Search vendor "Double Precision Incorporated"
Courier Mail Server
Search vendor "Double Precision Incorporated" for product "Courier Mail Server"
0.48
Search vendor "Double Precision Incorporated" for product "Courier Mail Server" and version "0.48"
-
Affected
Double Precision Incorporated
Search vendor "Double Precision Incorporated"
Courier Mail Server
Search vendor "Double Precision Incorporated" for product "Courier Mail Server"
0.48.1
Search vendor "Double Precision Incorporated" for product "Courier Mail Server" and version "0.48.1"
-
Affected
Double Precision Incorporated
Search vendor "Double Precision Incorporated"
Courier Mail Server
Search vendor "Double Precision Incorporated" for product "Courier Mail Server"
0.48.2
Search vendor "Double Precision Incorporated" for product "Courier Mail Server" and version "0.48.2"
-
Affected
Double Precision Incorporated
Search vendor "Double Precision Incorporated"
Courier Mail Server
Search vendor "Double Precision Incorporated" for product "Courier Mail Server"
0.49.0
Search vendor "Double Precision Incorporated" for product "Courier Mail Server" and version "0.49.0"
-
Affected
Double Precision Incorporated
Search vendor "Double Precision Incorporated"
Courier Mail Server
Search vendor "Double Precision Incorporated" for product "Courier Mail Server"
0.50.0
Search vendor "Double Precision Incorporated" for product "Courier Mail Server" and version "0.50.0"
-
Affected
Double Precision Incorporated
Search vendor "Double Precision Incorporated"
Courier Mail Server
Search vendor "Double Precision Incorporated" for product "Courier Mail Server"
0.52.1
Search vendor "Double Precision Incorporated" for product "Courier Mail Server" and version "0.52.1"
-
Affected